2020 CVE Vulnerabilities
21,075 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-10506 | HIGH | 7.5 | 1.3% | Apr 15, 2020 | The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversa... |
| CVE-2020-10505 | CRITICAL | 9.8 | 1.1% | Apr 15, 2020 | The School Manage System before 2020, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of SQL Injection... |
| CVE-2020-11767 | LOW | 3.1 | 1.8% | Apr 15, 2020 | Istio through 1.5.1 and Envoy through 1.14.1 have a data-leak issue. If there is a TCP connection (negotiated with SNI o... |
| CVE-2020-5260 | HIGH | 7.5 | 10.0% | Apr 14, 2020 | Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host cont... |
| CVE-2020-11765 | MEDIUM | 5.5 | 1.7% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by Dw... |
| CVE-2020-11764 | MEDIUM | 5.5 | 1.8% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp. |
| CVE-2020-11763 | MEDIUM | 5.5 | 1.8% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated b... |
| CVE-2020-11762 | MEDIUM | 5.5 | 1.8% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress i... |
| CVE-2020-11761 | MEDIUM | 5.5 | 1.8% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during Huffman uncompression, as demonst... |
| CVE-2020-11760 | MEDIUM | 5.5 | 1.8% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompres... |
| CVE-2020-11759 | MEDIUM | 5.5 | 1.7% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. Because of integer overflows in CompositeDeepScanLine::Data::handleDeep... |
| CVE-2020-11758 | MEDIUM | 5.5 | 1.8% | Apr 14, 2020 | An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read in ImfOptimizedPixelReading.h. |
| CVE-2020-11005 | MEDIUM | 5.5 | 0.2% | Apr 14, 2020 | The WindowsHello open source library (NuGet HaemmerElectronics.SeppPenner.WindowsHello), before version 1.0.4, has a vul... |
| CVE-2020-11003 | HIGH | 8.1 | 0.5% | Apr 14, 2020 | Oasis before version 2.15.0 has a potential DNS rebinding or CSRF vulnerability. If you're running a vulnerable applicat... |
| CVE-2020-11001 | MEDIUM | 6.8 | 1.3% | Apr 14, 2020 | In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scripting (XSS) vulnerability exists on the page revision compa... |
| CVE-2020-8327 | HIGH | 7.8 | 0.4% | Apr 14, 2020 | A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bu... |
| CVE-2020-8324 | MEDIUM | 5.5 | 0.3% | Apr 14, 2020 | A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.... |
| CVE-2020-8319 | HIGH | 7.8 | 0.4% | Apr 14, 2020 | A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that c... |
| CVE-2020-8318 | HIGH | 7.8 | 0.4% | Apr 14, 2020 | A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation... |
| CVE-2020-8316 | MEDIUM | 4.4 | 0.3% | Apr 14, 2020 | A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to r... |
| CVE-2020-9384 | HIGH | 8.8 | 1.9% | Apr 14, 2020 | An Insecure Direct Object Reference (IDOR) vulnerability in the Change Password feature of Subex ROC Partner Settlement ... |
| CVE-2020-7575 | MEDIUM | 6.1 | 0.6% | Apr 14, 2020 | A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (... |
| CVE-2020-7574 | MEDIUM | 6.1 | 0.6% | Apr 14, 2020 | A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (... |
| CVE-2020-6225 | HIGH | 8.8 | 1.1% | Apr 14, 2020 | SAP NetWeaver (Knowledge Management), versions (KMC-CM - 7.00, 7.01, 7.02, 7.30, 7.31, 7.40, 7.50 and KMC-WPC 7.30, 7.31... |
| CVE-2020-6217 | MEDIUM | 6.1 | 0.7% | Apr 14, 2020 | SAP NetWeaver AS ABAP Business Server Pages Test Application IT00, versions 700, 701, 702, 730, 731, 740, 750, 751, 752,... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now